Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Portugal, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Lei 58/2019 derogation from this timeline was identified in this pass.
What it asks of an app →
Comprehensive regime
cite Lei n.o 58/2019, de 8 de agosto
stage In effect
since 2019-08-08
source Diario da Republica Eletronico, dre.pt, official text listing
Portugal's private-sector regime is the General Data Protection Regulation (GDPR) plus Lei n.o 58/2019, de 8 de agosto (Lei de Execucao do RGPD, GDPR Implementation Law), in effect from its 8 August 2019 publication.
Portugal is genuinely divergent here: the CNPD, in Deliberacao n.o 2019/494 of 3 September 2019, announced it would decline to apply a set of Lei 58/2019's own provisions in its enforcement decisions, on the ground that those provisions restrict the GDPR's direct effect and full effectiveness contrary to the primacy of EU law.
This is not a repeal (the CNPD has no constitutional-court power to strike a provision down) and it does not bind the courts, which remain free to reach their own view if a disapplied provision is litigated; it is a supervisory authority's own prospective enforcement stance, published for transparency.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Portugal outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Lei 58/2019 derogation broadening or narrowing this was identified in this pass.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Art. 22; Lei n.o 58/2019, de 8 de agosto
stage In effect
since 2019-08-08
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Lei 58/2019 without narrowing per its own summary.
One of the CNPD's disapplied provisions, Lei 58/2019 Article 20(1) (restricting access rights where a confidentiality or secrecy duty applies against the data subject), sits in this dimension: only one of three secondary sources read this pass names Article 20(1) among the disapplied provisions, so this document does not treat that specific finding as settled, and the GDPR Article 12 to 23 baseline is recorded as controlling.
What it asks of an app →
Enforcement supervision
cite CNPD Deliberacao n.o 2019/494, de 3 de setembro de 2019; Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2019-09-03
source Three independent secondary paraphrases of CNPD Deliberacao 2019/494 (Lexology, Garrigues, Recording Law)
The CNPD is Portugal's supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. In Deliberacao n.o 2019/494 of 3 September 2019, the CNPD announced it will not apply a defined set of Lei 58/2019's own provisions in its enforcement practice, reasoning that an EU regulation has direct effect and primacy over conflicting national law under Article 288 TFEU and settled CJEU case law.
Three independent secondary paraphrases of the deliberation (Lexology, Garrigues, Recording Law) agree the CNPD disapplies Article 28(3)(a) (restricting employee consent to processing that would grant a legal or economic advantage) and a penalties-framework provision in the Article 37 to 39 range (differentiated fine ceilings by company size, and a prior-warning requirement for negligent infringements); the three sources diverge on the rest of the disapplied list (Articles 61(2), 62(2), and 20(1) are each named by only some of the three), so this document records only what all three corroborate and does not assert a complete article list.
Two direct attempts to read the deliberation's own primary text failed this pass (an HTTP 403 behind bot protection, and unparseable compressed PDF structure at two mirrors). GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Lei 58/2019 provision adding a distinct national biometric-specific derogation was identified in this pass; Lei 58/2019's own additions are concentrated in automated-decision rights and the CNPD's disapplication practice rather than a biometric-specific chapter.
No Portugal-specific voiceprint or faceprint case, deliberation, or regulatory guidance was located; this is recorded as an absence in this pass's search, not a confirmed absence in Portuguese law.
What it asks of an app →